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DETAILED ACTION 

1 . Claims 1 -20 are presented for examination. 

Response to Amendment 

2. Applicant's arguments filed January 26, 2007 have been fully considered 
but they are not persuasive because of the following reasons: 

3. Applicant argues that Win does not teach or suggest the feature of 
enabling the first server... to determine user access control data for identifying at least 
one user privilege for performing one or more actions and at least one user permission 
associated with one or more objects, wherein the remote repository is located within a 
second server, the second server being different from the first server. In response to 
applicant's argument, the examiner submits that Win does teach or suggest enabling 
the first server to apply the authentication process to authenticate the user against a 
remote repository for verifying the user credential input (figures 1, 3, 5, col. 6, lines 41- 
col. 7, line 67 -the access server 106 authenticates/verifies user name/password with 
Registry sever 108 ) and to determine user access control data for identifying at least 
one user privilege for performing one or more actions and at least one user permission 
associated with one or more objects (abstract, col. 5, line 66-col. 6, line 17, col. 8, lines 
5-23, col. 1 1 , lines 42-64 -providing user a personalized menu that displays only 
resources that user has a right to access according to user's profile, including user's 
role and privileges), wherein the remote repository is located within a second server, the 
second server being different from the first server (figure 1 , col. 6, lines 20-26 and 41-54 
- the registry repository 110 at the registry server 108 that stores user information, 
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resources, users' role that can be used by access server 106 to authorize user's 
privileges and wherein the access server 106 and registry server 108 are different). 

4. Applicant argues that Win does not teach or suggest enabling the first 
server to apply the authentication process to authenticate the user against a remote 
repository for verifying the user credential input. In response to applicant's argument, 
the examiner asserts that Win does clearly teach access server 106 includes 
authentication client module to authenticate a user by verifying the name and password 
with the registry server 108, wherein the registry server 108 comprises an 
authentication server module and a registry repository, wherein the authentication 
server module handles remote procedure calls from the access server 106 to retrieve 
information from registry repository 110 for authentication (figures 1, 3, 5, col. 6, lines 
20-col. 7, line 67, col. 12, lines 10-31 -the access server 106 authenticates/verifies user 
name/password with Registry sever 108). Thus, the examiner concludes that Win does 
clearly teach the feature of enabling the first server to apply the authentication process 
to authenticate the user against a remote repository for verifying the user credential 
input as disclosed in the claimed invention. 

5. Applicant argues that Win fails to teach or suggest determining user 
access control data for identifying at least one user privilege for performing one or more 
actions and at least one user permission associated with one or more objects. In 
response to applicant's argument, the examiner submits that Win does teach the feature 
of determining user access control data for identifying at least one user privilege for 
performing one or more actions and at least one user permission associated with one or 
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more objects as shown in abstract, col. 5, line 66-col. 6, line 17, col. 8, lines 5-23, col. 
1 1 , lines 42-64 (i.e., providing user a personalized menu that displays only resources 
that user has a right to access according to user's profile, including user's role and 
privileges). 

6. Applicant argues that Win fails to teach or suggest the remote repository is 
located within a second server, the second server being different from the first server. 

In response to applicant's argument, the examiner asserts that Win teaches the registry 
repository 1 10 at the registry server 108 that stores user information, resources, users' 
role that can be used by access server 106 to authorize user's privileges and wherein 
the access server 106 and registry server 108 are different as shown in figure 1, col. 6, 
lines 20-26 and 41-54. Therefore, the examiner concludes that Win does teach the 
remote repository is located within a second server, the second server being different 
from the first server as disclosed in the claimed invention. 

7. As a result, cited prior art does disclose a system and method for 
integrating security and user account data in a reporting system, as broadly claimed by 
the Applicants. Applicants clearly have still failed to identify specific claim limitations 
that would define a clearly patentable distinction over prior art. 

8. Therefore, the examiner asserts that cited prior art teaches or suggests 
the subject matter broadly recited in independent claims 1, 8 and 15. Claims 2-7, 9-14, 
and 16-20 are also rejected at least by virtue of their dependency on independent 
claims and by other reasons set forth in this office action below. Accordingly, claims 1- 
20 are rejected. 
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Claim Rejections - 35 USC § 102 

9. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 
§ 102 that form the basis for the rejections under this section made in this Office action: 
A person shall be entitled to a patent unless -- 

(e) the invention was described in (1) an application for patent, published under section 122(b), by 
another filed in the United States before the invention by the applicant for patent or (2) a patent 
granted on an application for patent by another filed in the United States before the invention by the 
applicant for patent, except that an international application filed under the treaty defined in section 
351(a) shall have the effects for purposes of this subsection of an application filed in the United States 
only if the international application designated the United States and was published under Article 21(2) 
of such treaty in the English language. 

OR 

e) the invention was described in a patent granted on an application for patent by another filed in the 
United States before the invention thereof by the applicant for patent, or on an international application 
by another who has fulfilled the requirements of paragraphs (1), (2), and (4) of section 371(c) of this 
title before the invention thereof by the applicant for patent. 



The changes made to 35 U.S.C. 102(e) by the American Inventors Protection Act 
of 1999 (AIPA) and the Intellectual Property and High Technology Technical 
Amendments Act of 2002 do not apply when the reference is a U.S. patent resulting 
directly or indirectly from an international application filed before November 29, 2000. 
Therefore, the prior art date of the reference is determined under 35 U.S.C. 102(e) prior 
to the amendment by the AIPA (pre-AlPA 35 U.S.C. 102(e)). 



10. Claims 1-20 are rejected under 35 U.S.C. § 102(e) as being anticipated 
by Win et al. (hereinafter Win) U.S. Patent No. 6,453,353. 
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11. As to claim 1 , Win teaches the invention as claimed, including a method 
for integrating security and user account data in a reporting system with at least one 
remote repository comprising the steps of: 

enabling a user to submit user credential input to a reporting system (figure 1 , 
col. 5, lines 12-20, col. 6, lines 20-40 -receiving user registers/log-in to the 
system/central repository/registry repository at a registry server)] 

identifying an authentication process (figure 1, col. 6, lines 41 -col. 7, line 6); 

forwarding the user credential input to a first server (figures 1, 3, 5, col. 8, line 5- 
col. 10, line 33 -forwarding to access server 106 for authentication)] and 

enabling the first server to apply the authentication process to authenticate the 
user against a remote repository for verifying the user credential input (figures 1,3,5, 
col. 6, lines 41 -col. 7, line 67 -the access server 106 authenticates/verifies user 
name/password with Registry sever 108 ) and to determine user access control data for 
identifying at least one user privilege for performing one or more actions and at least 
one user permission associated with one or more objects (abstract, col. 5, line 66-col. 6, 
line 17, col. 8, lines 5-23, col. 11, lines 42-64 -providing user a personalized menu that 
displays only resources that user has a right to access according to user's profile, 
including user's role and privileges), wherein the remote repository is located within a 
second server, the second server being different from the first server (figure 1 , col. 6, 
lines 20-26 and 41-54 - the registry repository 1 10 at the registry server 108 that stores 
user information, resources, users' role that can be used by access server 106 to 
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authorize user's privileges and wherein the access server 106 and registry server 108 
are different). 

12. As to claim 2, Win teaches the invention as claimed, further comprising a 
step of importing user information from the remote repository (figure 1, col. 5, lines 12- 
20, col. 6, lines 20-26, col. 7, lines 45-57). 

13. As to claim 3, Win teaches the invention as claimed, wherein the 
authentication process comprises Lightweight Directory Access Protocol (col. 12, lines 
10-53). 

14. As to claim 4, Win teaches the invention as claimed, wherein the 
authentication process comprises an operating system authentication (figures 1, 3, 5, 
col. 6, lines 41 -col. 7, line 67). 

15. As to claim 5, Win teaches the invention as claimed, further comprising a 
step of enabling the server to synchronize user account data with the user information 
from the remote repository (col. 7, lines 34-67, col. 19, line 50-col. 20, line 53). 

16. As to claim 6, Win teaches wherein the user is associated with a group of 
users wherein group information from the remote repository is imported (figure 1, col. 5, 
lines 12-20, col. 6, lines 20-26, col. 7, lines 45-57). 
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17. As to claim 7, Win teaches the invention as claimed, wherein the user 
information comprises at least one or user permissions, privileges and access rights 
associated with the user (abstract, col. 5, line 66-col. 6, line 17, col. 8, lines 5-23, col. 
11, lines 42-64). 

18. As to claim 8, Win teaches the invention as claimed, including a system 
for integrating security and user account data in a reporting system with at least one 
remote repository, comprising: 

an input for enabling a user to submit user credential input to a reporting system 
(figure 1, col. 5, lines 12-20, col. 6, lines 20-40 -receiving user registers/log-in to the 
system/central repository) ; 

an identification module for identifying an authentication process (figure 1, col. 6, 
lines 41-col. 7, line 6); 

a forwarding module for forwarding the user credential input to a first server 
(figures 1 , 3, 5, col. 8, line 5-col. 10, line 33 -forwarding to access server 106 for 
authentication)] and 

a first server for applying the authentication process to authenticate the user 
against a remote repository for verifying the user credential input (figures 1, 3, 5, col. 6, 
lines 41-col. 7, line 67 -the access server 106 authenticates/verifies user 
name/password with Registry sever 108) and to determine user access control data for 
identifying at least one user privilege for performing one or more actions and at least 
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one user permission associated with one or more objects (abstract, col. 5, line 66-col. 6, 
line 1 7, col. 8, lines 5-23, col. 1 1 , lines 42-64 -providing user a personalized menu that 
displays only resources that user has a right to access according to user's profile, 
including user's role and privileges), wherein the remote repository is located within a 
second server, the second server being different from the first server (figure 1, col. 6, 
lines 20-26 and 41-54 - the registry repository 110 at the registry server 108 that stores 
user information, resources, users' role that can be used by access server 106 to 
authorize user's privileges and wherein the access server 106 and registry server 108 
are different). 

19. As to claim 9, Win teaches the invention as claimed, further comprising an 
import module for importing user information from the remote repository (figure 1 , col. 5, 
lines 12-20, col. 6, lines 20-26, col. 7, lines 45-57). 

20. As to claim 10, Win teaches the invention as claimed, wherein the 
authentication process comprises Lightweight Directory Access Protocol (col. 12, lines 
10-53). 

21 . As to claim 1 1 , Win teaches the invention as claimed, wherein the 
authentication process comprises an operating system authentication (figures 1, 3, 5, 
col. 6, lines 41 -col. 7, line 67). 
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22. As to claim 12, Win teaches the invention as claimed, wherein the server 
synchronizes user account data with the user information from the remote repository 
(col. 7, lines 34-67, col. 19, line 50-col. 20, line 53). 

23. As to claim 13, Win teaches wherein the user is associated with a group of 
users wherein group information from the remote repository is imported (figure 1, col. 5, 
lines 12-20, col. 6, lines 20-26, col. 7, lines 45-57). 

24. As to claim 14, Win teaches the invention as claimed, wherein the user 
information comprises at least one or user permissions, privileges and access rights 
associated with the user (abstract, col. 5, line 66-col. 6, line 17, col. 8, lines 5-23, col. 
1 1 , lines 42-64). 

25. As to claim 15, Win teaches the invention as claimed, including a 
processor-readable medium comprising code for execution by a processor to integrate 
security and user account data in a reporting system with at least one remote 
repository, the medium comprising: 

code for causing a processor to enable a user to submit user credential input to a 
reporting system (figure 1 , col. 5, lines 12-20, col. 6, lines 20-40 -receiving user 
registers/log-in to the system/central repository)] 

code for causing a processor to identify an authentication process (figure 1, col. 
6, lines 41 -col. 7, line 6); 
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code for causing a processor to forward the user credential input to a first server 
(figures 1, 3, 5, col. 8, line 5-col. 10, line 33 -forwarding to access server 106 for 
authentication): and 

code for causing a processor to enable the first server to apply the authentication 
process to authenticate the user against a remote repository for verifying the user 
credential input (figures 1 , 3, 5, col. 6, lines 41 -col. 7, line 67 -the access server 106 
authenticates/verifies user name/password with Registry sever 108) and to determine 
user access control data for identifying at least one user privilege for performing one or 
more actions and at least one user permission associated with one or more objects 
(abstract, col. 5, line 66-col. 6, line 17, col. 8, lines 5-23, col. 1 1 , lines 42-64 -providing 
user a personalized menu that displays only resources that user has a right to access 
according to user's profile, including user's role and privileges), wherein the remote 
repository is located within a second server, the second server being different from the 
first server (figure 1 , col. 6, lines 20-26 and 41-54 - the registry repository 110 at the 
registry server 108 that stores user information, resources, users' role that can be used 
by access server 106 to authorize user's privileges and wherein the access server 106 
and registry server 108 are different). 

26. As to claim 16, Win teaches the invention as claimed, further comprising 
code for causing a processor to import user information from the remote repository 
(figure 1, col. 5, lines 12-20, col. 6, lines 20-26, col. 7, lines 45-57). 
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27. As to claim 17, Win teaches the invention as claimed, wherein the 
authentication process comprises at least one of Lightweight Directory Access Protocol 
and operating system authentication (col. 12, lines 10-53). 

28. As to claim 18, Win teaches the invention as claimed, further comprising 
code for causing a processor to enable the server to synchronize user account data with 
the user information from the remote repository (col. 7, lines 34-67, col. 19, line 50-col. 
20, line 53). 

29. As to claim 19, Win teaches wherein the user is associated with a group of 
users wherein group information from the remote repository is imported (figure 1, col. 5, 
lines 12-20, col. 6, lines 20-26, col. 7, lines 45-57). 

30. As to claim 20, Win teaches the invention as claimed, wherein the user 
information comprises at least one or user permissions, privileges and access rights 
associated with the user (abstract, col. 5, line 66-col. 6, line 17, col. 8, lines 5-23, col. 
1 1 , lines 42-64). 

Conclusion 

31. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of 
time policy as set forth in 37 CFR 1.136(a). 
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A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within 
TWO MONTHS of the mailing date of this final action and the advisory action is not 
mailed until after the end of the THREE-MONTH shortened statutory period, then the 
shortened statutory period will expire on the date the advisory action is mailed, and any 
extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of 
the advisory action. In no event, however, will the statutory period for reply expire later 
than SIX MONTHS from the mailing date of this final action. 

32. Any inquiry concerning this communication or earlier communications from 
the examiner should be directed to Thu Ha Nguyen, whose telephone number is (703) 
305-7447. The examiner can normally be reached Monday through Friday from 8:00 
AM to 6:00 PM. 

33. If attempts to reach the examiner by telephone are unsuccessful, the 
examiner's supervisor, Glenton Burgess, can be reached at (571) 272-3949. 

Any inquiry of a general nature of relating to the status of this application should 
be directed to the Group receptionist whose telephone number is (703) 305-9600. 

The fax phone numbers for the organization where this application or proceeding 
is assigned are 703-872-9306 for regular communications. 

Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
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For more information about the PAIR system, see http://pair-direct.uspto.gov . Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). 




January 14, 2008 



